3 ms·
x.sh was just the script I used to automatically register all the packages. It takes one argument, a package name, then attempts to publish that package. So
by nmjohn 11y ago
x.sh was just the script I used to automatically register all the packages.
It takes one argument, a package name, then attempts to publish that package.
So
cat list | xargs -I{} ./x {}
was what I used to publish the whole list.
- zamalek 11y agoIt seems as though, unintentionally, you've found a pretty big vulnerability. Either way, kudos for parking these packages until they find a new home - this could have turned out so much worse.
- drinchev 11y agoHey really sorry for what happened. Anyway did you think of explaining your intend to doing so? I've been doing development for years and I've never seen a developer naming files "x.sh", except if it was not malicious.